// 1 CRITICAL · 6 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
VULNCRITICAL

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger

CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

Jul 17, 2026views - 1.4k

CYBERSECCRITICAL

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE

Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…

Jul 17, 2026views - 1.3k

CYBERSEC

Windows WMI: ZDI-26-415 Vulnerability Allows Escalation to SYSTEM

CVE-2026-49805 in Windows WMI Providers enables local privilege escalation to SYSTEM. Microsoft has released patches and rates exploit…

Jul 17, 2026views - 1.4k

CYBERSEC

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon

ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

Jul 16, 2026views - 1.3k

CYBERSECZERO-DAY

MSI Center: LPE Vulnerability in NTIOLib_X64.sys Kernel Driver

ZDI-26-430 discloses a local privilege escalation to SYSTEM in the NTIOLib_X64.sys driver used by MSI Center. The flaw affects OEM har…

Jul 16, 2026views - 1.5k

CYBERSECCRITICAL

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available

ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

Jul 16, 2026views - 1.5k

VULNZERO-DAY

G DATA Total Security: LPE in Backup Service, SYSTEM Compromised via Symlink

ZDI-26-432 (CVE-2026-13268, CVSS 7.8) details a symbolic link following attack in the G DATA Total Security Backup Service. Here is th…

Jul 16, 2026views - 1.4k

CYBERSECCRITICAL

ZDI-26-438: RCE in Rockwell Arena Simulation via DOE File, Patch Available

The ZDI-26-438 vulnerability enables remote code execution in Rockwell Automation Arena Simulation through malicious DOE files. Coordi…

Jul 16, 2026views - 1.3k

CYBERSEC

ArcGIS Server Path Traversal Masqueraded as Moderate: CVSS Jumps from 7.5 to 9.8 in Two Days

Esri updated the CVE-2026-9181 record on July 8, 2026, raising the CVSS score from 7.5 to 9.8. The NVD–CNA discrepancy risked leaving…

Jul 14, 2026views - 1.6k

CYBERSEC

SAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks

CVE-2026-44747 is an out-of-bounds write in the SAP NetWeaver ABAP kernel with total impact on confidentiality, integrity, and availab…

Jul 14, 2026views - 1.3k

microsoftZERO-DAY

Microsoft July 2026 Patch Tuesday: Record Vulnerability Volume Forces a Reckoning

Microsoft's July 2026 Patch Tuesday delivers a record-breaking number of vulnerabilities. Two zero-days are already under active explo…

Jul 14, 2026views - 1.4k

CYBERSECZERO-DAY

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough

SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

Jul 14, 2026views - 1.3k